Road to Cyber Essentials
A growing construction company with no formal IT management achieved Cyber Essentials certification in just 8 weeks. From scattered devices and no policies to a fully compliant, managed IT environment.
Growing Pains Without IT Structure
This construction company had grown from a small team to a substantial operation over several years. IT had evolved organically—staff bought their own laptops, used personal email for work, and there was no central oversight of devices or data.
When pursuing larger contracts, they discovered that Cyber Essentials certification was increasingly becoming a requirement. They had no internal IT expertise and no idea where to start.
Key challenges we identified:
- Mix of personal and business devices with no central management
- No formal email system—staff using various personal accounts
- No security policies or acceptable use guidelines
- Inconsistent software versions and no patch management
- No VPN for site-based staff accessing company resources
- Paper-based processes with no secure document storage
Structured Path to Certification
We designed an 8-week programme that would establish proper IT foundations while preparing for Cyber Essentials certification. The approach balanced quick wins with sustainable long-term improvements.
Week 1-2: Foundation
Deployed Microsoft 365 Business Premium for all staff. Migrated email to professional domain. Enrolled all devices in Intune for central management. Established baseline security policies.
Week 3-4: Security Controls
Configured firewall rules and network segmentation. Deployed endpoint protection. Enforced MFA across all accounts. Set up hosted VPN for remote site access. Implemented automatic patching.
Week 5-6: Policy & Training
Created acceptable use policy, password policy, and incident response procedures. Delivered staff training session covering email security, password hygiene, and reporting suspicious activity.
Week 7-8: Assessment & Certification
Completed internal pre-assessment. Addressed any gaps identified. Submitted Cyber Essentials self-assessment questionnaire. Achieved certification.
Certified and Contract-Ready
The company achieved Cyber Essentials certification within the 8-week timeframe, but the benefits went far beyond the certificate.
CE Certified
First-time pass
£200k+
New contracts won
100%
Devices now managed
Staff Trained
Security awareness
"We went from having no IT management to being Cyber Essentials certified in two months. The process was straightforward and the team explained everything in terms we could understand. We've already won contracts we couldn't have bid for before."
— Director, Construction CompanyThe client now operates with proper IT foundations: centralised device management, professional email, secure remote access for site staff, and documented policies. They're currently working towards Cyber Essentials Plus for the following year.
Need Cyber Essentials Certification?
We'll get you certified with minimal disruption. Clear timeline, fixed price, no surprises.
Related Case Studies
Security Assessment & Remediation
Comprehensive security review leading to full remediation and managed services.
Business Premium Security Rollout
Taking organisations from basic M365 to fully secured environments.
Migration to Microsoft 365
Seamless migration from Google Workspace with zero downtime.
